In short
RCSA stands for Risk and Control Self-Assessment. It is a structured process where the first line (the people who run the processes) identify risks, map the controls that mitigate them, and assess whether those controls are designed and operating as intended - with second-line oversight.
- Owned by - the first line; facilitated by the second line.
- Output - an evidence-backed view of risk and control health, not a form filled in for audit.
- Why most fail - vague controls, disengaged first line, gaps captured but actions not closed, and an annual snapshot instead of continuous assessment.
- Same as - "risk and control assessment" is the same activity under a different label.
RCSA stands for Risk and Control Self-Assessment. It is the structured process the first line uses to identify risks, map the controls that mitigate them, and assess whether those controls are designed and operating as intended. Many firms call the same activity a risk and control assessment.
If you work in or around operational risk, the acronym is never far away. Regulators expect it. Internal policies reference it. And every year, someone sends a spreadsheet asking business owners to "please confirm your controls are effective."
Yet many programmes quietly fail. Not because people are careless, but because the process is manual, subjective, and disconnected from how the business actually runs. This article sets out what risk and control assessment / RCSA is for, why it exists, where it typically breaks, and what a credible programme looks like in the real world.
What Is an RCSA? What Is Risk and Control Assessment?
In plain terms, risk and control assessment is a structured way for the first line (the people who own and run the processes) to identify the risks in their area, map the controls that mitigate those risks, and assess whether those controls are designed and operating as intended. An RCSA is the same idea expressed as a formal self-assessment cycle - usually owned by the business, with second-line oversight.
The output is not just a form filled in for audit. It should be an evidence-backed view of risk and control health that second line can challenge, aggregate, and report - and that management can use to prioritise investment, remediation, and monitoring.
- Risks - what could go wrong in the process, product, or activity.
- Controls - the policies, procedures, system settings, checks, and approvals that reduce likelihood or impact.
- Assessment - a disciplined judgement (often supported by evidence) on design and effectiveness, not a box-ticking exercise.
Why Risk and Control Assessment (RCSA) Exists
Risk and control assessment - whether you run it as a labelled RCSA or embed it in broader operational risk routines - sits at the intersection of governance and operational reality. Boards and regulators want confidence that risks are understood where they arise - not only in a central risk register written by specialists. Self-assessment is the mechanism for pushing ownership to the front line while preserving oversight.
Done well, it also creates a common language between business units, risk, compliance, and audit: the same risk IDs, the same control definitions, and a clear line of sight from incidents and issues back to the control environment.

